Researchers Use AI to Exploit OpenAI Software Flaws
Researchers used AI to exploit flaws in OpenAI software, gaining access to staff accounts and internal repositories.
Intelligence analysis by Qwen 2.5 (3B)

Researchers found and exploited two flaws in OpenAI's software, gaining access to staff accounts and internal repositories. The flaws were in the forum software and OpenAI's login system.
Researchers found two bugs in OpenAI's software. They used a smart computer program (AI) to find the bugs and then used the bugs to get into a special computer system. This shows that even smart programs can find and use bugs to get into important systems.
Analysis
{"#OpenAI Login Flaw":"OpenAI's login system was vulnerable to a flaw in the Discourse forum software. The flaw allowed researchers to take over staff accounts by chaining together two vulnerabilities. The flaw was in the libheif library, which is used to read uploaded images. The researchers used AI to exploit the flaw and gain access to the internal repository.","#Libheif Flaw":"The libheif flaw was a memory out-of-bounds read that could crash the software or leak nearby memory. The researchers combined this flaw with the AI's help to turn the crash into working code execution on the forum server. The fix for the libheif flaw was already public, but Debian had not yet included it in the packaged version the forum used.","#AI Usage":"The researchers used Claude Opus 5, a more advanced AI model, to exploit the flaws. Claude Opus 5 was able to produce a working exploit within hours, while the previous model, Claude Opus 4.8, struggled over several sessions."}
Key points
- Researchers found and exploited two flaws in OpenAI's software
- The flaws were in the forum software and OpenAI's login system
- The researchers used AI to exploit the flaws and gain access to the internal repository
This research helps improve security by finding and fixing bugs in software. It also shows that AI can be used for good, like finding and reporting bugs.
If the bugs were used for bad, they could have caused problems. This research shows that we need to be careful about who has access to important software and systems.


